Re: Mixed HTTPS/non-HTTPS content in IE9 and Chrome 13 dev [and WebSockets in FF6]

2011-06-08 Thread Christopher Blizzard
On 6/7/2011 5:52 PM, Adam Barth wrote: On Tue, Jun 7, 2011 at 5:43 PM, Brian Smithbsm...@mozilla.com wrote: Adam Barth wrote: On 5/31/2011 8:24 AM, Brian Smith wrote: We have also discussed blocking https+ws:// content completely in our WebSockets implementation, so that all WebSockets on a

Re: Mixed HTTPS/non-HTTPS content in IE9 and Chrome 13 dev [and WebSockets in FF6]

2011-05-31 Thread Christopher Blizzard
On 5/31/2011 8:24 AM, Brian Smith wrote: We have also discussed blocking https+ws:// content completely in our WebSockets implementation, so that all WebSockets on a HTTPS page must be wss://. That way, we could avoid making mixed content problems any worse. Do you have a bug on file for

Re: Content Security Policy feedback

2010-08-19 Thread Christopher Blizzard
You guys should add Arun + Jonas to this conversation if you can. --Chris ___ dev-security mailing list dev-security@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security

Re: Browser security in the XO aka OLPC aka $100 laptop

2010-08-19 Thread Christopher Blizzard
Check with Marco Gritti m...@redhat.com. He's the guy doing all the browser work. --Chris On Apr 3, 2008, at 2:06 AM, Xavier Vergés wrote: Thanks, Boris I haven't asked them (still don't know where they hang out), but I'm under the impression that they are running plain Xulrunner, using

Re: Who is using NSS in their projects?

2010-03-03 Thread Christopher Blizzard
On 3/3/2010 10:40 AM, Shailendra Jain wrote: I also heard that Linux is planning to integrate NSS as main security features for Linux. Is that true? That's true, but I'm not sure how deep it goes. --Chris ___ dev-security mailing list